--- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: labels: app.kubernetes.io/instance: external-secrets app.kubernetes.io/name: external-secrets app.kubernetes.io/version: v0.15.1 rbac.authorization.k8s.io/aggregate-to-admin: "true" rbac.authorization.k8s.io/aggregate-to-edit: "true" rbac.authorization.k8s.io/aggregate-to-view: "true" name: external-secrets-view rules: - apiGroups: - external-secrets.io resources: - externalsecrets - secretstores - clustersecretstores - pushsecrets - clusterpushsecrets verbs: - get - watch - list - apiGroups: - generators.external-secrets.io resources: - acraccesstokens - clustergenerators - ecrauthorizationtokens - fakes - gcraccesstokens - githubaccesstokens - quayaccesstokens - passwords - vaultdynamicsecrets - webhooks - grafanas - generatorstates verbs: - get - watch - list